8.6

CVE-2020-29491

Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to gain access to the sensitive information on the local network, leading to the potential compromise of impacted thin clients.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Wyse Thinos Version <= 8.6
   Dell ≫ Wyse 3040 Version -
   Dell ≫ Wyse 5010 Version -
   Dell ≫ Wyse 5040 Version -
   Dell ≫ Wyse 5060 Version -
   Dell ≫ Wyse 5070 Version -
   Dell ≫ Wyse 5470 Version -
   Dell ≫ Wyse 7010 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.85% 0.763
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.6 3.9 4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
EMC 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

https://www.dell.com/support/kbdoc/en-us/000180768/dsa-2020-281
Vendor Advisory